Synology NFS Vulnerability – CVE-2025-1021
A critical security vulnerability has been discovered in Synology’s DiskStation Manager (DSM) software, allowing remote attackers to read arbitrary files through the Network File System (NFS) service without proper authorization.
Tracked as CVE-2025-1021, this flaw was detailed in a Synology security advisory and has been addressed in recent updates. It affects multiple versions of the widely used network-attached storage (NAS) operating system.
Details of the Vulnerability:
The issue, rated as “Important” with a CVSS v3.1 Base Score of 7.5, originates from a missing authorization check in the DSM’s “synocopy” component. This flaw enables unauthenticated attackers to bypass security measures and access sensitive files via a writable NFS service.
According to Synology’s technical disclosure (initially published on February 26, 2025, and updated on April 23, 2025), the vulnerability is characterized by the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N — indicating:
- Network-based exploitability
- Low attack complexity
- No privileges or user interaction required
- High impact on confidentiality
This makes the vulnerability particularly dangerous, as attackers can remotely read files without any authentication.
Recommended Action:
Organizations utilizing Synology NAS devices are urged to update their systems immediately to mitigate the risk of unauthorized data access.
Acknowledgment:
The vulnerability was discovered by the DEVCORE Research Team (https://devco.re/), a group renowned for uncovering critical flaws in enterprise software and hardware systems.
| Category | Description |
|---|---|
| Affected Products | DSM versions earlier than 7.1.1-42962-8, 7.2.1-69057-7, and 7.2.2-72806-3 |
| Impact | Enables remote attackers to read arbitrary files, potentially leading to exposure of sensitive information |
| Exploit Prerequisites | No authentication or user interaction required; attacker must have network access to a writable NFS service |
| CVSS 3.1 Score | 7.5 (“Important” severity) |
Affected Products and Remediation
This vulnerability impacts several versions of Synology’s DiskStation Manager (DSM) operating system:
- DSM 7.2.2: Update to version 7.2.2-72806-3 or later.
- DSM 7.2.1: Update to version 7.2.1-69057-7 or later.
- DSM 7.1: Update to version 7.1.1-42962-8 or later.
Synology has confirmed that no workarounds or mitigations are available. Applying the security updates is the only way to address the vulnerability, making timely patching critical.
Recommendations for Users
Security specialists advise Synology users to take the following immediate actions:
- Verify the DSM version installed on all Synology devices.
- Apply the recommended updates based on your current DSM version.
- Review NFS share configurations and permissions to minimize unnecessary exposure.
- Monitor system logs for any suspicious activities that could suggest prior exploitation.
This vulnerability underscores the critical importance of regularly updating network-attached storage (NAS) devices, particularly those accessible over the internet or corporate networks.
Users are strongly urged to prioritize patching efforts to safeguard sensitive data against potential breaches.




